CVE-2021-20194
Vulnerability Summary
Timeline
Description
There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger bug in __cgroup_bpf_run_filter_getsockopt() function that can lead to heap overflow (because of non-hardened usercopy). The impact of attack could be deny of service or possibly privileges escalation.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v2.0•MEDIUM•Score: 4.6AV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 0.40%• Percentile: 34%
Techniques & Countermeasures
- CWE-20•Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
- CWE-787•Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Affected Systems
- chainguard•hyperv-daemons-6.18
< 0
- chainguard•hyperv-daemons-generic
< 0
- chainguard•linux-aws-6.12
< 6.12.65-r0 | < 0
- chainguard•linux-aws-6.12-boot-installed
< 0
- chainguard•linux-aws-6.12-fips-boot-installed
< 0
- chainguard•linux-aws-6.12-headers
< 0
- chainguard•linux-aws-6.12-modules
< 0
- chainguard•linux-aws-6.18
< 6.18.10-r0 | < 0
- chainguard•linux-aws-6.18-boot-installed
< 0
- chainguard•linux-aws-6.18-fips-boot-installed
< 0
- chainguard•linux-aws-6.18-headers
< 0
- chainguard•linux-aws-6.18-modules
< 0
- chainguard•linux-aws-generic
< 6.18.5-r0 | < 0
- chainguard•linux-aws-generic-boot-installed
< 0
- chainguard•linux-aws-generic-fips-boot-installed
< 0
- chainguard•linux-aws-generic-headers
< 0
- chainguard•linux-aws-generic-modules
< 0
- chainguard•linux-azure-6.12
< 6.12.65-r1 | < 0
- chainguard•linux-azure-6.18
< 0
- chainguard•linux-azure-6.18-boot-installed
< 0
- chainguard•linux-azure-6.18-fips-boot-installed
< 0
- chainguard•linux-azure-6.18-headers
< 0
- chainguard•linux-azure-6.18-modules
< 0
- chainguard•linux-azure-generic
< 6.18.5-r0 | < 0
- chainguard•linux-azure-generic-boot-installed
< 0
- chainguard•linux-azure-generic-fips-boot-installed
< 0
- chainguard•linux-azure-generic-headers
< 0
- chainguard•linux-azure-generic-modules
< 0
- chainguard•linux-desktop-6.18
all
- chainguard•linux-desktop-6.18-bootc
all
- chainguard•linux-desktop-6.18-bootc-boot-installed
all
- chainguard•linux-desktop-6.18-headers
all
- chainguard•linux-desktop-6.18-modules
all
- chainguard•linux-desktop-7.2
all
- chainguard•linux-desktop-7.2-bootc
all
- chainguard•linux-desktop-7.2-bootc-boot-installed
all
- chainguard•linux-desktop-7.2-modules
all
- chainguard•linux-firecracker-6.18
all
- chainguard•linux-gcp-6.12
< 0 | < 6.12.65-r0
- chainguard•linux-gcp-6.18
< 0 | < 6.18.10-r0
- chainguard•linux-gcp-6.18-boot-installed
< 0
- chainguard•linux-gcp-6.18-fips-boot-installed
< 0
- chainguard•linux-gcp-6.18-headers
< 0
- chainguard•linux-gcp-6.18-modules
< 0
- chainguard•linux-gcp-generic
< 0 | < 6.18.5-r0
- chainguard•linux-gcp-generic-boot-installed
< 0
- chainguard•linux-gcp-generic-fips-boot-installed
< 0
- chainguard•linux-gcp-generic-headers
< 0
- chainguard•linux-gcp-generic-modules
< 0
- chainguard•linux-qemu-6.12
< 6.12.71-r0
Showing first 50 affected entries in server-rendered view.
References (10)
- https://bugzilla.redhat.com/show_bug.cgi?id=1912683
- https://security.netapp.com/advisory/ntap-20210326-0003/
- https://ubuntu.com/security/CVE-2021-20194
- https://patchwork.kernel.org/project/netdevbpf/patch/20210122164232.61770-1-loris.reiff@liblor.ch/#23921223
- https://ubuntu.com/security/notices/USN-4879-1
- https://ubuntu.com/security/notices/USN-4884-1
- https://ubuntu.com/security/notices/USN-4909-1
- https://ubuntu.com/security/notices/USN-4912-1
- https://www.cve.org/CVERecord?id=CVE-2021-20194
- https://security-tracker.debian.org/tracker/CVE-2021-20194